runpod-usage

Pass

Audited by Gen Agent Trust Hub on Aug 5, 2026

Risk Level: SAFENO_CODEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill consists exclusively of Markdown documentation. No executable code or scripts are included in the package.\n- [NO_CODE]: The package does not contain operational code, eliminating risks associated with local script execution.\n- [EXTERNAL_DOWNLOADS]: Setup instructions refer to official installation scripts for runpodctl and uv hosted on vendor and well-known domains (runpod.net, astral.sh).\n- [COMMAND_EXECUTION]: Guidance is provided for using shell tools and SSH to manage cloud resources, reflecting the skill's purpose for infrastructure automation.\n- [PROMPT_INJECTION]: The skill documentation describes workflows where an agent processes user-provided infrastructure configurations. An indirect prompt injection surface is noted as no explicit sanitization or boundary markers are instructed. Ingestion points: User parameters in reference/pod-workflows.md. Boundary markers: Absent. Capability inventory: High (runpodctl, SSH). Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 5, 2026, 06:05 AM
Security Audit — agent-trust-hub — runpod-usage